Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wf43-55jj-vwq8

Опубликовано: 15 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

DNS Rebinding in etcd

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

Пакеты

Наименование

go.etcd.io/etcd

go
Затронутые версииВерсия исправления

< 3.4.0

3.4.0

EPSS

Процентиль: 21%
0.00067
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-20
CWE-350

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

CVSS3: 5
redhat
почти 8 лет назад

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

CVSS3: 5.5
nvd
почти 8 лет назад

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

CVSS3: 5.5
debian
почти 8 лет назад

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attack ...

EPSS

Процентиль: 21%
0.00067
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-20
CWE-350